CVE-2024-5148: Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate

Published May 20, 2024
·
Updated

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

Other sources

Description: gnome-remote-desktop system daemon does inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. Furthermore, it may be possible for a malicious user on the system to take control of the RDP client connection during the login screen to user session transition.

Affected version: 46.alpha through 46.1

Fixed version: 46.2 (forthcoming)

Reference: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/196

Red Hat

gnome-remote-desktop fails to validate up front that the caller of methods on handover objects matches the user associated with the session involved with the handover process.

Ubuntu

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

4 affected componentsFixes available
ubuntu/gnome-remote-desktop<46.2-1~ubuntu24.04.2
46.2-1~ubuntu24.04.2
ubuntu/gnome-remote-desktop<46.2
46.2
debian/gnome-remote-desktop
0.1.7-10.1.9-543.3-144.2-8
redhat/gnome-remote-desktop<46.2
46.2

Event History

May 22, 2024
CVE Published
via Ubuntu·12:00 AM
May 27, 2024
Data Sourced
via Launchpad·05:29 PM
Description
Sep 2, 2024
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2024-5148?

CVE-2024-5148 has been rated as a medium severity vulnerability due to inadequate validation of session agents.

2

How do I fix CVE-2024-5148?

To fix CVE-2024-5148, upgrade the gnome-remote-desktop package to version 46.2 or later.

3

What systems are affected by CVE-2024-5148?

CVE-2024-5148 affects the gnome-remote-desktop package on Ubuntu, Debian, and Red Hat systems.

4

Who is responsible for managing the gnome-remote-desktop security updates related to CVE-2024-5148?

Security updates for gnome-remote-desktop related to CVE-2024-5148 are managed by the respective maintainers of Ubuntu, Debian, and Red Hat.

5

What consequences can arise from not addressing CVE-2024-5148?

Failing to address CVE-2024-5148 can lead to unauthorized access or exploitation of remote desktop sessions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203